9 ms·
Fastmail offers EU data region
- cjs_ac 2mo ago[flagged]
- I_am_tiberius 2mo agoAnd which company hosts the data? An American company like Aws, Azure, Google or a European company like OVH, Stackit?
- techpression 2mo ago> We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers. This new location is built to the same high standards as our existing infrastructure in Philadelphia and St Louis, with our own hardware and our own software — specified right down to the exact model of disks in each machine.
- fhdkweig 2mo agoThe flagged/dead comment contains a copy of the entire page, but the relevant part is: > Built by us, not rented from someone else > We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers. This new location is built to the same high standards as our existing infrastructure in Philadelphia and St Louis, with our own hardware and our own software — specified right down to the exact model of disks in each machine. > In all our locations, data is stored encrypted at rest inside locked racks, and managed by our in-house team. We don’t rent computing or management services from a big cloud provider and pass on their assurances. That’s how we’ve approached privacy, reliability, and performance for more than 25 years.
- PeterStuer 2mo agoFive Eyes country are subject to local data disclosure orders and gag clauses, forcing them to hand over user data that may then enter the shared intelligence pool
- skywal_l 2mo agoThere are no Five Eyes country in the EU.
- throw1234567891 2mo agothey offer services in the EU
- r_lee 2mo agothe company is based in Australia, which is part of FVEY
- anon48293 2mo agoNo, but there are nine eyes and fourteen eyes with EU countries.
- PeterStuer 2mo agoIs fastmail not australian?
- senderista 2mo agoNot sure Five Eyes will outlast Trump, the UK has reportedly stopped sharing some intelligence with the US: https://www.courthousenews.com/uk-faces-questions-on-complicity-in-us-boat-strikes-after-pausing-intel-sharing/ https://www.courthousenews.com/uk-faces-questions-on-complic...
- kazen44 2mo agosame goes for dutch intelligence agencies and i highly doubt others inside the EU sharing data willy nilly. https://nos.nl/artikel/2586859-aivd-en-mivd-delen-minder-info-met-vs-en-meer-met-europa-zeggen-directeuren https://nos.nl/artikel/2586859-aivd-en-mivd-delen-minder-inf...
- robin_reala 2mo agoPosted on the previous submission for this: it’s a good start, but from the article: If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.
- intothemild 2mo agoWow they completely missed the ball on why people want reassurances that their data stays in the EU
- xnickb 2mo agoI think they just know what they can and can't guarantee.
- linux2647 2mo agoAgreed. I imagine they’ll announce an EU-only option later once they get more EU infrastructure in place
- jeffrallen 2mo agoAs long as they are owned by a 5-eyes nation, there's no alternative they can offer. Instead, look to Exoscale, Proton, Infomaniak, or Scaleway. Disclaimer: I work for one of 'em.
- fodkodrasz 2mo agoFor me this is already a better value proposition, as less value add happens in the US. With the US being a perpetrator in trade war against the EU, even this matters. Everything counts, in large amounts...
- nektro 2mo agothey also said in the article it is dependent on them standing up a second EU region. this is simply an announcement of their first.
- deleted 2mo ago[deleted]
- altairprime 2mo agoEU folks, note the warnings threaded throughout this post: this is not currently any sort of panacea against US or AU data hosting risks, but it will make your data noticeably closer to home. Fastmail (Australia) merged with Pobox (Philadelphia) resulting in a complex tri-national law/risk surface when the EU is involved, so go in eyes wide open having read this in full. That everyone will overinterpret “EU data region” to mean “for privacy” here until reading the article is completely understandable; I empathize, having done the same.
- usernomdeguerre 2mo agoI think it's not unreasonable to see this as a first, positive, step. It's certainly giving them some benefit of the doubt, but it doesn't seem unreasonable that, say, the EU server and the US backup will in some time be an EU server and an EU backup.
- altairprime 2mo agoIndeed; see also the top thread discussing that, as I don’t have anything to add to the ground already covered: https://news.ycombinator.com/item?id=49223931 https://news.ycombinator.com/item?id=49223931
- inigyou 2mo agoIt's either a positive step or it's a deceptive step. It could be to actually improve data security, or it could be to make it look like they're improving data security.
- afiori 2mo agoAlso the more companies go in this direction the more "soft power" the EU has on the topic
- jacquesm 2mo agoEU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US (or: five-eyes) owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happened. There are only very few such stacks that are 100% owned by EU entities.
- selectively 2mo ago[dead]
- V__ 2mo agoFor anyone curious, it's the CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil. [1] https://en.wikipedia.org/wiki/CLOUD_Act https://en.wikipedia.org/wiki/CLOUD_Act
- samudrijan 2mo agoThe point of control is Congress, until we stop electing corpratist politicians, we will continue to get bad legislation.
- redserk 2mo agoIt doesn't matter if it's Congress. At the end of the day America's internal governance systems are America's problem. The rest of the world should not care if a certain branch is causing issues, and frankly, is starting to come to that conclusion. It's unfortunate for us, but we very rarely isolate individual government systems for other nations.
- braiamp 2mo agoWhich wouldn't matter where the data is located, so I don't think that this is the reason Fastmail is doing it, because a savvy enough company would know that the problem is that the company is US based.
- honeycrispy 2mo ago[flagged]
- flexagoon 2mo agoChat Control 1.0 is a permanent extension of a temporary law that already existed a year ago, allowing the companies to scan your messages if they want to. Nothing changed since then.
- lrae 2mo agoYou mean Chat Control 1.0 that was already in place from 2021 to April 2026 and allows for voluntary scanning for CSAM in unecrypted data through hash-matching for existing and indexed CSAM material?
- KingOfCoders 2mo agoWe offer EU data centers for customers that want their emails to stay in the EU but "Resilient replicas of your data will live in the US" ?
- crossroadsguy 2mo agoThe US data replicas will be resilient, and when the FBI asks your data to reveal things about itself, your data will refuse to reveal anything about itself in the characteristic resilient manner. That's why the mention of "resilient".
- KingOfCoders 2mo agoHow is that possible if the OS/drive/vault is backdoored? Could you elaborate? I think "resilient" just means "backup copy" and I do think (IANAL) it is illegal to destroy emails when asked for them in the US. Or was your comment ironic? Sorry, German, irony impaired.
- Night_Thastus 2mo agoThey're being sarcastic.
- cube2222 2mo agoNice, as a European customer, I appreciate this. Side note, I moved to Fastmail a couple years ago, and so far I’ve been very happy with it! The Gmail migrator works great, too.
- EPWN3D 2mo agoLove them, but I wish they had a way to upload new sieve rules via an API. I'm probably going to try them with my own domain at some point since I think they have an option to just deliver all mail bound for that domain, which makes setting up random emails for dodgy sites really easy.
- catgirlinspace 2mo agoI assume they support this part of JMAP https://jmap.io/spec/rfc9661/ https://jmap.io/spec/rfc9661/
- EPWN3D 2mo agoTheir FAQ says you must use the web interface to edit your rules. But this is worth a shot.
- catgirlinspace 2mo agoah, I wasn't aware of that.
- cube2222 2mo agoYep, you can enable a catch-all for anything that’s not a predefined alias. I’m using that setup and have no issues with it, for exactly the use-case you mentioned.
- Marciplan 2mo agousing cirrux.me and very happy with an actual EU hosted option (Team is Dutch)
- varispeed 2mo agoData is still compellable through US Cloud Act (and other provisions). If you want true EU data region, you should buy from a company without presence in the US.
- crossroadsguy 2mo agoI have never understood their 50+10 GB storage as the starting plan. Anyone storing a lot of emails, please don't come at me screaming, but know that not everyone keeps every email and every attachment ever received right there in that email account (especially the attachments). For me, email is just communication i.e timed information, not data storage, except for very personal emails, and very very rare, some non-personal important emails. So some people do like to simply delete the emails they no longer need. Also their pricing almost feels like "unlimited storage" backup solutions mass pricing strategy.
- tene80i 2mo agoYou mean why isn’t there a cheaper tier than $5/mo? Not much to be gained by offering it, I would think.
- 3eb7988a1663 2mo agoEven at cloud prices, 50GB of storage is ~$1/month. Offering an additional tier with pathetic storage to save $0.80 or whatever is muddling the offering. I guess they could offer a 0GB storage option that only operated as a relay?
- lschueller 2mo agoIf what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise. Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)
- deleted 2mo ago[deleted]
- vzaliva 2mo agoI do not know any EU-only, but ProtonMail is in Switzerland.
- petcat 2mo agoProton is leaving Switzerland because of surveillance and privacy issues. > Because of legal uncertainty around Swiss government proposals to introduce mass surveillance — proposals that have been outlawed in the EU — Proton is moving most of its physical infrastructure out of Switzerland. https://proton.me/blog/lumo-ai https://proton.me/blog/lumo-ai They are moving to Germany, but will quickly find that they are going to face the same surveillance and privacy issues since the EU is in the process of negotiating a data sharing agreement under the US Cloud Act. https://www.justice.gov/archives/opa/pr/justice-department-and-european-commission-announces-resumption-us-and-eu-negotiations https://www.justice.gov/archives/opa/pr/justice-department-a...
- preisschild 2mo agoThat was 2023 before the 2nd Trump Admin and before the Privacy and Civil Liberties Oversight Board that was supposed to be independent and protect against abuse has resigned.
- atmosx 2mo agoDepends on the definition and your threat model but to make a very large story short; it’s email, others have copies (your gmail friends?). Metadata is public by default the body can be encrypted and encrypted at rest (comes with many limitations) and that’s the highest level of security you can realistically achieve. If that works fine if not, use another method of comm. Email wasn’t designed to be secure.
- atmosx 2mo agoOkay, that solves two problems for me. Great news.
- kmfrk 2mo agoAs a European and Fastmail user, this is great news.
- greenleafone7 2mo agoThe article states that they do not offer any guarantee that my data will stay in the EU! I feel that that's the whole point. And the whole point of them making this article/advertisement.
- petcat 2mo agoHow could they possibly guarantee such a thing? Do you only send and receive emails with people in the EU?
- monsieurbanana 2mo agoAt the moment all your data is still replicated in the US (they say it will change in the future, sure) and all the logs are also stored there, with no plans to change it or more details into what they contain. As of now there's no guarantee of... anything, really. Obviously if you decide to send an email to the US you're choosing to send your data there, that's a strawman.
- preisschild 2mo agoIts not about the people you send emails to, its about who has access to your entire mailbox. In the moment that would be the Trump Administration for example.
- greenleafone7 2mo agoYour reply is dishonest. I obviously couldn't replicate the entire article, but I'm assuming everyone that reads my comment also has read the article. And so you know very well what I meant. If you advertise foolproof safes, but they end up not in fact being exactly that very thing you advertised then I'm sure you will have a great reason as to why actually your 'foolproof' safe can not be foolproof and you never guaranteed such a thing in your tos. But at the end of the day, you promised foolproof safes, and you did not deliver. Your argument is "well if you leave the lock open then...". And the reply to that argument is that "yes, we all know". The fact that I the user can make a mistake, does not excuse the company from saying "well, anyway, he would have made a mistake anyway so why bother"
- rzerowan 2mo agoSeeing a lot of detail in the comments about the CLOUD act which applies as they(fastmail) themselves have an equivalent that was signed between USgov and Australia. The more concerning issue as far as Australian based tech is The Assistance and Access Act 2018 which "...permits government enforcement agencies to force businesses to hand over user info and data even though it’s protected by cryptography. If firms don’t have the power to intercept encrypted data for authorities, they will be forced to create tools to allow law enforcement or government to have access to their users’ data." As far as i know this has not been challenged or walked back and with the rise of ChatControl like laws doesnt seem it will.
- chrismorgan 2mo agoThe Assistance and Access Act is completely irrelevant to Fastmail, because Fastmail doesn’t offer end-to-end encryption. Fastmail was always subject to the Telecommunications Act, which allows Australian police access with warrants, and Fastmail has always made it clear that it complies with legal warrants.
- denismi 2mo agoThe article you're quoting [1] concerns itself with the creation of systemic "encryption-breaking" capabilities and exploits which said law bends over backwards to expressly prohibit [2]. [1] https://fee.org/articles/australia-s-unprecedented-encryption-law-is-a-threat-to-global-privacy/ https://fee.org/articles/australia-s-unprecedented-encryptio... [2] https://classic.austlii.edu.au/au/legis/cth/consol_act/ta1997214/s317zg.html https://classic.austlii.edu.au/au/legis/cth/consol_act/ta199...
- egorfine 2mo agoCan't wait to verify my age before reading emails! In all seriousness though, what are the chances Fastmail won't require KYC at some point? I have sent them a support request with that question and got a non-answer. PS: Am a paying customer for like a decade
- crossroadsguy 2mo agoNo one would know that other than Fastmail and regulators. But what I can say is keeping different emails for different purposes might be the way. Unless your domain also has none of your PII attached to you, neither is any of your email interactions. It's not ideal but I finally stopped fighting it and use few emails that offers both privacy and anonymity if I ever need that.
- tamimio 2mo agoDoes it matter much? From one side, you are still in the 14 eyes countries (in fact, I would trust a Chinese server if i am living in the west and vice versa), on another side, emails as a protocol was never meant to be secure or private, so deal with it as that, if you are after private or secure communication, choose a protocol that provides that, adding more stuff to emails will only complicate it further plus giving false sense of privacy/security, gpg will leak meta data, receiver email server/client might expose you too, among many gaps, so just avoid it. Still, make sure your email spf dkim dmarc etc are set properly and carry on.
- superq 2mo agoEU data regions are based on the insanely flawed idea that data is: * a physical thing that can only live in one place * not copyable * can be 'contained'. The whole thing reeks of bureaucratic 'best practices' that just aren't. Even worse than that, trying to keep email restricted to the EU (or anywhere else) means that you effectively wouldn't be able to communicate with anyone in a different region, which is kinda the whole point. Why not just make your own internet next? and then you can disconnect from everyone else who is trying to hack you. Just pull your network plug. Email itself is hopelessly insecure by design anyway. Not just metadata when you are E2EE everything inside the envelope, but even basic vulns like downgrade attacks are simple because it's literally a violation of the RFCs (so you're not spec-compliant) to require TLS or any other encryption.. Why? because requiring modern crypto might interfere with deliverability and backwards compatibility. The real, deeper reason is that email is from a kinder, simpler time (well, at least simpler) and the design goals were never updated to keep up with the times. Email is what we have. Just understand its flaws and then use other tools where you can. And who cares where your email lives - it's too easy to break anyway.
- preisschild 2mo agoThis is not an EU law anyways, this is snakeoil companies acting like having their data located in the EU will change who has access to it and will make it "GDPR compliant" (it wont since the CLOUD ACT still applies)
- plqbfbv 2mo ago> The CLOUD Act authorizes bilateral agreements between the United States and trusted foreign partners that will make both nations’ citizens safer, while at the same time ensuring a high level of protection of those citizens’ rights. I think the keywords are "trusted" and "citizens' rights". US burned a lot of trust in the last few years, and what's happening with ICE doesn't really scream "citizens' rights" either. I can see why many "trusted foreign partners" would now think twice rather than help out the US compared to just 5 years ago. As a EU person, I'd really like to not have ties with US when possible, and I'd really like to foster the economy of non-US alternatives.
- sparkling 2mo agoTo me, jurisdiction matters more than physical location. I'd rather be with a EU-operated service that stores data on a non-EU server, than a non-EU operator with a German/french datacenter.
- rb666 2mo agoFinally! I have been asking for this since the US started to lose its mind. Great they are listening.
- preisschild 2mo agoBut this is completely worthless, they still fall under the cloud act. Trump Admin still has access to your mailbox.
- ln809 2mo agoSecondary copy not in EU. So how exactly does that help with compliance?
- leros 2mo agoIt sounded like a temporary situation until they get a second EU datacenter.
- plqbfbv 2mo agoAs a customer, thank you, Fastmail. I recall reading a few months back that this was rumored to be in the works, glad it panned out.
- victorbjorklund 2mo agoNot more safe. Only safe way is to use a company not under US regulation.
- jgeerts 2mo ago[dead]
- Cider9986 2mo agoJurisdiction is an outdated way of looking at things. End-to-end encryption is what actually matters. Of course, people are stupid, so it continues.
- tremon 2mo agoE2E encryption is meaningless for an e-mail hosting provider; they are by necessity one of the E's.
- tumdum_ 2mo agoOr you can just use any of the actual European companies (I’m using Tuta). https://european-alternatives.eu/category/email-providers https://european-alternatives.eu/category/email-providers
- dwedge 2mo agoI started using tuta until I realised they don't support IMAP. Something to do with not guaranteeing encryption (which isn't even enabled by default) but has the convenient effect of locking you into their apps
- gertop 2mo agoTuta is always encrypted I don't know where you got the impression that it was optional or that they could somehow magically make it work over IMAP without a bridge like proton.
- globular-toast 2mo agoPGP works over IMAP.
- dwedge 2mo ago> Tuta does not support the use of third-party email clients or the protocols IMAP/POP3/SMTP as we cannot guarantee end-to-end encryption of your data. So it "breaks end to end encryption" even with smtps and imaps apparently. The few emails I received weren't from tutamail users so presumably came over SMTP. It's confusing to know what they mean because they confuse terms. They say emails are "stored end to end encrypted". They don't pass my smell test
- doener 2mo agoAs long as the company's legal headquarters are in the U.S., U.S. agencies have access to the data under the Cloud Act—and non-U.S. citizens have absolutely no legal recourse when it comes to U.S. services
- hinata08 2mo agotheir HQ is supposed to be in Melbourne, Australia They mention it only briefly in their publication. Their about page is clearer about that.
- doener 2mo agoAh, thanks for the hint! Probably better than, but still Five Eyes. The legal details I‘m not aware of in this case.
- tremon 2mo agoWhich means that not even a European subsidiary will prevent data exfiltration by FVEY. Australia can just issue a TCN to the parent company to add a backdoor to the software used by the European subsidiary.
- ThePowerOfFuet 2mo agoTotally irrelevant because of the CLOUD Act. Aussie law might be even worse than US; I would never use Fastmail.
- user00005 2mo agoThe local government cannot get access to the servers in Amsterdam? I use Fastmail but just consider it safe from third party advertisers. If I wanted safety from governments I would use something else, or at least encrypt my email contents.
- trocado 2mo agoThis may not have much practical consequence, but still there's some symbolic value which is welcomed in today's geopolitical climate.
- igl 2mo agoAustralian company so: lol. Snowden triggered a few narrow real wins but the broader surveillance apparatus adapted, survived, and in some ways grew. Things were just legalised.
- inigyou 2mo agoUseless. US companies have to get EU citizen's data on request. They can and must do so. Only non-US companies can ignore US data requests.
- daft_pink 2mo agoActually thrilled that I can choose US data residency. Apparently, it was always that way? Happy that I can choose it though as I would prefer my data not be stored somewhere else.
- 8by3 2mo agoIts not only a question of five eyes access. There is also the concern of being subject to the whims of a regime that might decide you shouldn't have access to services hosted in their country.
- procaryote 2mo agoThis does nothing to resolve that
- braza 2mo agoMaybe it’s a silly question, but how much of those “EU Region” makeups that were seeing are enforceable in reality? In extreme cases the US DoJ can reach, let’s say the CEO/CTO arrest them or pick up family members in case of some sort of non-compliance in some criminal investigation. I can imagine something like > US DoJ has some PoI with some account in Fastmail “EU region” > Fastmail says “sorry we’re GDPR” > US DoJ says “now” or… > Fastmail refuses Then what?
- deleted 2mo ago[deleted]
- kazen44 2mo agothen it becomes a political issue between the EU and the US? mind you, prior to this administration the EU was more then happy to help the US DOJ in such cases. considering the stuff that happened in the past year or so, i doubt that would happen again. Actually calling bluff on the US is the only way to play this properly, because it gives the EU a mandate to strike back geopolitically if the US wants to retaliate for non-compliance by fastmail.
- zecg 2mo ago> Resilient replicas of your data will live in the US (for now). As we only have one location in Europe so far, the geographically separate copy will remain on servers in one of our US locations. Wow, it's nothing. How about writing your PR after the data is not going to the US at all?
- tikkabhuna 2mo agoIsn't it a step in that direction? The first data centre in Europe shows a commitment and it will likely be easier to do the next data centre(s).
- wasabi359 2mo ago[flagged]
- hn_submit 2mo agoI call this "sovereignty washing": American companies pretending they can magically free themselves from the U.S. CLOUD Act by setting up a paper European presence. Anyone who falls for this is a fool wanting to be fooled.
- pigbearpig 2mo agoInteresting take considering Fastmail is very clearly not an American company.
- jnrk 2mo agoFastmail is Australian though.
- philipwhiuk 2mo ago> Emergency backups for everybody are stored in our Philadelphia location. As well as the live replicas of your data, we also keep a separate set of encrypted backups taken every few hours for every account. These are in Philadelphia for all users at the moment. So all of this is pointless.
- _tk_ 2mo agoUnfortunately, even if all data lives in the European Union, as long as a company is conducting business in the US, the Cloud Act makes it possible to compel them to hand over any information. This can include making administrative personnel sign NDAs or face heavy repercussions. Conducting business in the US includes advertising to US citizens e.g through maintaining a website in English. At this point it’s unclear what a future digitally sovereign infrastructure should look like. Even if a company or a European state somehow manages to store data that is out of reach for the US Government, an amendment to FISA or the Cloud Act is something that any Congress should be able to put together.
- telmo 2mo agoI am pretty sure that European states are already storing data that is out of reach for the US government, and I don't understand how Congress could legislate against this, short of an act of war.
- _tk_ 2mo agoThere are certainly exceptions, but a lot of European Governments use Azure or Google for their office applications, including different law enforcement agencies and militaries.
- telmo 2mo agoIndeed. My point, however, is that Congress cannot pass legislation to compel European governments to share data with the US if/when they decide not to. OP is making a weird claim about the practical impossibility of escaping US data collection.